Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →EU AI Act (Regulation (EU) 2024/1689)
Issued by
European Commission
- September 30, 2026 · Substantive update — Rewrote the entry to cover the whole EU AI Act, including Regulation (EU) 2026/1744. Corrected the date the bans and AI literacy duty took effect from February 2026 to 2 February 2025. (Cody Maxwell)
The EU AI Act is the European Union's law on artificial intelligence. It sorts AI systems by risk, bans a short list of practices, and sets duties for high-risk systems and general-purpose AI models. It applies to any organization that builds, sells, or uses AI in the EU, wherever that organization is based. Obligations phase in between February 2025 and August 2028.
Applies To
Overview
The EU AI Act (Regulation (EU) 2024/1689) is the European Union's main law on artificial intelligence. It entered into force on 1 August 2024. It covers providers, the organizations that build an AI system or put it on the market, and deployers, the organizations that use one in their work. It also reaches companies outside the EU when their AI is used in the EU. The Act sorts AI by risk. A short list of practices is banned outright, including social scoring, manipulation that exploits people's vulnerabilities, untargeted scraping of facial images, and emotion recognition at work or in schools. High-risk systems, such as AI used in hiring, credit scoring, education, and critical infrastructure, must meet strict requirements before use. Systems that talk to people or generate content carry transparency duties. Everything else is minimal risk and largely unregulated. General-purpose AI models, the large models behind chatbots and coding assistants, have their own rules. Providers must keep technical documentation, publish a summary of their training content, and follow EU copyright law. Models classed as posing systemic risk, the most capable ones, carry extra duties. These include safety evaluations, serious incident reporting, and cybersecurity protections. Obligations phase in over several years. The bans and the AI literacy duty have applied since 2 February 2025. The general-purpose AI rules, governance provisions, and penalties followed on 2 August 2025. Regulation (EU) 2026/1744 then moved the high-risk deadlines. Stand-alone high-risk systems now have until 2 December 2027, and AI built into regulated products has until 2 August 2028. The same amendment added two bans from 2 December 2026 and softened the AI literacy duty to one of supporting staff literacy. National market surveillance authorities enforce the Act in each member state. The European AI Office supervises general-purpose AI models. Fines reach EUR 35 million or 7% of worldwide annual turnover for banned practices, whichever is higher. Most other breaches carry fines of up to EUR 15 million or 3%.
Key Requirements
- •Stop any banned practice listed in Article 5. The original bans have applied since 2 February 2025.
- •Stop any AI system that generates child sexual abuse material or non-consensual intimate images, banned from 2 December 2026.
- •Take measures that support AI literacy among staff who operate or oversee AI, matched to their role (Article 4, as amended in 2026).
- •Classify every AI system you build or use against the Act's risk tiers, and record the reasoning.
- •For high-risk systems, providers need risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity controls, a conformity assessment, and registration in the EU database.
- •Deployers of high-risk systems must follow the provider's instructions, assign trained people to oversee the system, keep its logs, and inform affected workers. Public bodies and some private deployers must also assess the impact on fundamental rights.
- •Tell people when they are dealing with an AI system, and label deepfakes and other AI-generated content (Article 50).
- •Providers of general-purpose AI models must keep technical documentation, publish a training content summary, and adopt a copyright policy. Models with systemic risk carry extra duties.
What Your Organization Must Do
- →Build an inventory of the AI systems you use or develop, including tools bought from vendors, and classify each one against the risk tiers.
- →Confirm that no system falls into a banned category, including the two bans added for December 2026, and record that review with a named owner.
- →Run a role-based AI literacy program and keep training records you can show a regulator.
- →For each high-risk system, plan back from its deadline of 2 December 2027 or 2 August 2028. Book conformity assessment early, since the independent assessors who run it have limited capacity.
- →Add AI Act terms to vendor contracts: technical documentation, access to logs, incident notice, and evidence of conformity.
- →Check whether changing or rebranding a vendor's model would make you its provider, which brings the provider duties with it.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Governance Controls
Operational controls that implement requirements from this regulation.
Frequently Asked Questions
- When does the EU AI Act apply?
- The Act applies in stages, starting from its entry into force on 1 August 2024. The bans and the AI literacy duty have applied since 2 February 2025. General-purpose AI rules, governance provisions, and penalties have applied since 2 August 2025. Two added bans apply from 2 December 2026. After Regulation (EU) 2026/1744, stand-alone high-risk systems must comply by 2 December 2027, and AI built into regulated products by 2 August 2028.
- Does the EU AI Act apply to companies outside the EU?
- Yes, it applies when a company places an AI system on the EU market or when the system's output is used in the EU. Providers based outside the EU that offer high-risk systems or general-purpose AI models must appoint an authorised representative in the EU.
- What counts as a high-risk AI system?
- AI can be high-risk in two ways. The first is AI that works as a safety component of a product already covered by EU product law, such as a medical device or machinery (Annex I). The second is AI used in the eight areas listed in Annex III. Those areas are biometrics, critical infrastructure, education, employment, and access to essential services such as credit and insurance. They also include law enforcement, migration and border control, and justice and democratic processes.
- Which AI practices are banned?
- Article 5 bans manipulative techniques that cause significant harm, exploiting people's age, disability, or economic situation, and social scoring. It also bans predicting crime from personality traits alone, untargeted scraping of facial images, and emotion recognition at work or in schools. Biometric categorisation that infers sensitive traits is banned, and real-time remote biometric identification in public spaces for law enforcement is allowed only in narrow cases. From 2 December 2026, AI that generates child sexual abuse material or non-consensual intimate images of real people is banned too.
- What are the fines under the EU AI Act?
- Using a banned practice can cost up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. Most other breaches carry up to EUR 15 million or 3%. Giving regulators incorrect or misleading information carries up to EUR 7.5 million or 1%. Smaller companies pay the lower of the two amounts.
- Does the Act apply if we only use AI tools from vendors?
- Yes, because deployers have their own duties, including AI literacy, transparency to the people affected, and oversight of high-risk systems. A banned practice stays banned no matter who built the tool. Heavily modifying a vendor's system or selling it under your own name can also make you its provider.
